CVE-2021-3863: Cross-site Scripting (XSS) - Generic in snipe/snipe-it
Published Oct 19, 2021
·Updated
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
Snipeitapp Snipe-it<5.3.0
Remediation
Event History
Oct 19, 2021
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this snipe-it vulnerability?
The vulnerability ID for this snipe-it vulnerability is CVE-2021-3863.
2
What is the severity of CVE-2021-3863?
The severity of CVE-2021-3863 is medium with a score of 6.1.
3
Which version of snipe-it is affected by CVE-2021-3863?
Version up to and excluding 5.3.0 of snipe-it is affected by CVE-2021-3863.
4
What is the CWE category of CVE-2021-3863?
The CWE category of CVE-2021-3863 is CWE-79.
5
How do I fix CVE-2021-3863 snipe-it vulnerability?
To fix CVE-2021-3863 in snipe-it, it is recommended to update to a version that includes the fix, such as the commit mentioned in the references.